This could allow an authenticated highly-privileged remote attacker to read and write arbitrary files in the filesystem, if and only if the malicious path ends with 'log' .
Metrics
Affected Vendors & Products
Fri, 22 Aug 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens scalance Lpe9403 Firmware
|
|
CPEs | cpe:2.3:h:siemens:scalance_lpe9403:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:scalance_lpe9403_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Siemens scalance Lpe9403 Firmware
|
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 11 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit user controlled paths to which logs are written and from where they are read. This could allow an authenticated highly-privileged remote attacker to read and write arbitrary files in the filesystem, if and only if the malicious path ends with 'log' . | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2025-03-11T13:35:39.175Z
Reserved: 2025-02-24T10:03:33.207Z
Link: CVE-2025-27397

Updated: 2025-03-11T13:35:33.948Z

Status : Analyzed
Published: 2025-03-11T10:15:19.083
Modified: 2025-08-22T17:58:09.643
Link: CVE-2025-27397

No data.

Updated: 2025-07-12T15:26:10Z